Auth_HTTP glaring security hole
| From: | Ross Smith II | Date: | Mon, 06 May 2002 17:38:32 +0000 |
| Subject: | Auth_HTTP glaring security hole | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-5986@lists.php.net to get a copy of this message | ||
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Either I'm just dense, or Auth_HTTP has a huge security hole.
When I use Auth_HTTP and attempt to logout via:
$a->logout();
$a->start();
I'm not presented with the login dialog.
So I tried:
$a->logout();
$a->drawLogin();
Now I get the login dialog, but I'm able to subvert this, by simply
selecting Cancel, then clicking the
back button in my browser until the "logged in" page is displayed.
Any ideas on how to really logout in Auth_HTTP? After spending several
hours try to come up with a patch, the only way I've found to truly
"logout" is to close the browser window.
Should I give up Auth_HTTP and just use Auth? For technical reasons, I
would prefer to use Auth_HTTP.
Thanks,
Ross
-----BEGIN PGP SIGNATURE-----
Version: 6.5.8ckt http://www.ipgpp.com/
Comment: KeyID: 0xADAD77FB
Comment: Fingerprint: F54F FB60 33FF 1582 977C 8E3F A4DE 95E1 ADAD 77FB
iQA/AwUBPNa/laTeleGtrXf7EQIfdACbBRMWEUv8AgU1nK6h4ObWDTO7Q/YAn3uF
R2ZdpxC4AcwE2Xiu414HnnHY
=hH1r
-----END PGP SIGNATURE-----